Repository navigation
v1.10.0 — HPOS fraud statuses, REST credential check, rolling decline window
First release assembled from reviewed Codex pull requests (#2, #3, #4, #5, #6, #8).
Fixed
- Fraud orders were invisible on the HPOS Orders list. Statuses are now registered and stored as
wc-fraud-autoandwc-fraud-stripe, like WooCommerce's own. A one-time migration on the first request after updating rewrites the old values inwp_postsand the HPOS tables, backfills the persistent fraud flag, and clears caches, with direct SQL so no status hooks, notes, or emails fire. The combined Fraud view now exists on HPOS too, the Activity Log and Reports read the authoritative store, refunded fraud orders count in Reports, and alert emails use the HPOS-aware edit link. Usage-report counter key moves frommarked:fraud-auto-cancelledtomarked:fraud-auto. (#5) - REST hardening no longer trusts credential-like input. Only a request WooCommerce authenticated as a
manage_woocommerceuser, or one with a valid Store API nonce, passes. WooCommerce's own permission check already refused fake credentials, so this hardens the plugin's layer. (#3) - Repeated payment failures are counted over a true rolling 24 hours. Existing clusters keep their count for one more window. (#4)
- IP repeat tracking no longer grows without bound. One expiring transient per IP; the old
wcaf_ip_storeoption is removed on first use. (#6) - Post-payment rules never fall back to the request IP. (#6)
wcaf_suspicious_order_detectedalways receives three arguments. (#8)
Changed
- Every outbound request sends a
WC-Antifraud/<version> WordPress/<version>User-Agent instead of WordPress's default, which carries the site URL. README privacy section reworded. (#2)
Full details in CHANGELOG.md.